Poor HR leaves firms open to security risks

Mar 9, 2007 8:24 AM
Tags: poor | hr | leaves | firms | open | security | risks

'Employee education gap' putting employers and employees in danger.

Small UK businesses are leaving themselves vulnerable to unnecessary IT security risks because of poor human resources practices, it was claimed today.

A poll of over 1,000 SMEs (50-250 employees) across Europe conducted by McAfee found that only 32 percent have IT security as an aspect of employee induction.

The research indicated that the UK leads the induction drive, and that British businesses are the most likely to hold induction sessions for all employees.

However, more than a third of businesses in France and Italy do not have inductions for all employees.

Some 70 percent of respondents believe that employers are more sensitive to the risks associated with new employees than they were three years ago.

However, only 39 percent of businesses have guidelines for employees on email content/language, 28 percent for the use of portable storage devices and 23 percent for laptop use.

In the majority of cases where security issues are raised, most businesses feel that the end user is more culpable than the employer, highlighting serious implications for employee and employer liability.

For example, 55 percent felt that an employee should be held responsible for a personal email that spreads a virus on the company network.

Similarly a stolen laptop is also seen as the responsibility of the employee by 67 percent of respondents.

The research warned that current approaches may be "misguided" in terms of culpability for security breaches.

Although employee actions may result in security breaches, the employer is often ultimately responsible for the processes and conditions that surround security incidents.

Greg Day, security analyst at McAfee, said: "While many businesses make a priority of employee induction, many are failing effectively to cover a major part of any employees working life: their PC and internet usage policies.

"Companies are failing to capture the opportunity presented by new starters to instil a sense of vigilance and security into the workforce.

"This oversight, coupled with a clear lack of enforcement, increases the risk of new employees consciously or inadvertently breaching corporate security protocols."

Typically, inductions are shortest in Germany where 36 percent of businesses complete full HR inductions in fewer than three hours.

At the other end of the spectrum, Spanish inductions are most likely to take more than two days (32 percent of respondents), while UK and French businesses strike a balance at half a day.

Billy Hamilton Stent, a director at consultancy LoudHouse Research which undertook the study, said: "The induction process provides an ideal opportunity to engender a vigilant response to information security for end users. 

"It is not a case of issuing a list of dos and don'ts, but more a process of establishing trust, security and clear working procedures that reduce employee and employer risk. It is unfortunate that only a minority of businesses see it in this way."

Copyright ©v3.co.uk


  • Email a Friend
  • Print Page
Poor HR leaves firms open to security risks
 
Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Or log in now to comment
 
 
 
Top Stories
Oracle shuts down open source test servers
Playing nice with the open source community, Larry?
 
Google hosts election debate
Lundy, Fletcher and Ludlam face off on tech policies.
 
Telstra fined $18.5m for exchange access
Kept competitive DSLAM kit out.
 

Latest VideosSee all videos »

Latest Comments
"anyone who knows ANYTHING about RF knows how idiotic it is to have a "bare" antennae that will ..."
by Res Jul 31, 2010 10:00 AM
 
"Now Julia, if only you would promise not to filter the internet in your next term of government ..."
by hsvandrew Jul 31, 2010 9:33 AM
 
"@Nate - my fears are that if we use a national consortium as an interface to international ..."
by heavenlyhaloes Jul 31, 2010 12:41 AM
 
"Did anybody notice that on Apple's website the iPhone is missing the AT&T logo on the top bar? ..."
by brownenicola Jul 30, 2010 10:18 PM
 
"@digger11 - when will you learn just to remain quiet when you don't have all the facts or a ..."
by Bazwalt Jul 30, 2010 7:13 PM
Polls
Did Google breach the Telecommunications Interception or Privacy Acts during its WiFi wardrive?

   |   View results
Yes. There is no excuse for collecting this data.
  28%
 
No. If your wireless network is unsecured, you have no right to complain
  72%
TOTAL VOTES: 1873

Vote